Group Policy to OU

  • Thread starter Thread starter IMRAN
  • Start date Start date
I

IMRAN

I created group, added users to it, put the group in an OU and assigned a
policy to it, but the policy didn't apply. Why not?

I can accomplish this by creating GPO at domain level and add individual
group to it. why not from at OU level?

I have verified to make sure policy inheritance is not ON or enforced
checked at domain level. what could be the cause?



Any help will greatly appreciated, Thanks in an advance.





IMRAN



(e-mail address removed)
 
Thanks, It does seems to work when i add user in OU instead to group. what
is confusing is, if group policy does not apply to group then why it works
from domain level. i am using GPMC and i creat GPO and link from domain
then add group to it, works like a charm. why?
just a curiosity, for now my initial issue is resolved.

Thanks You, hth
 
Because from the domain level, everything in the domain is within the Scope
of Influence (or Management) through inheritance. If you apply a policy to
an OU, you're only affecting the objects directly within that OU (or sub
OU's from where you applied the policy). And GPO's do not apply to security
groups, but you can use a security group to /filter/ on the permissions tab.

Ken
 
I created group, added users to it, put the group in an OU and
assigned a policy to it, but the policy didn’t apply. Why not?

Step one in knowing Group Policy - Group Policies Don’t Apply to
groups or the users inside groups. They only apply to Users and
Computers Inside the OU that the GP is applied to. Groups are for
setting security permissions.

Cheers,

Lara
 
Hold up... I have a question about this. When I go into ADU&C and I right
click on my domain (Name.domain.com) and then to the Group Policy tab I have
a BUNCH of GPO's created. One of the policies is named "Domain Users" and
has a global security group named "Domain Users" applying the policy. This
security group contains all the normal domain users. When they log in this
policy DOES get applied but according to your post they should not be?

Thanks
 
Back
Top